VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,581)

page 41 of 80
  • CVE-2025-10231HigSep 10, 2025
    risk 0.46cvss 7.0epss 0.00

    An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-level user to run commands with elevated permissions.

  • CVE-2025-45467HigJul 25, 2025
    risk 0.46cvss 7.1epss 0.00

    Unitree Go1 <= Go1_2022_05_11 is vulnerable to Insecure Permissions as the firmware update functionality (via Wi-Fi/Ethernet) implements an insecure verification mechanism that solely relies on MD5 checksums for firmware integrity validation.

  • CVE-2025-49006HigJun 9, 2025
    risk 0.46cvss —epss 0.00

    Wasp (Web Application Specification) is a Rails-like framework for React, Node.js, and Prisma. Prior to version 0.16.6, Wasp authentication has a vulnerability in the OAuth authentication implementation (affecting only Keycloak with a specific config). Wasp currently lowercases…

  • CVE-2025-32981HigApr 25, 2025
    risk 0.46cvss 7.1epss 0.00

    NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File.

  • CVE-2025-24176HigJan 27, 2025
    risk 0.46cvss 7.1epss 0.00

    A permissions issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local attacker may be able to elevate their privileges.

  • CVE-2024-49724HigJan 21, 2025
    risk 0.46cvss 7.0epss 0.00

    In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected activities due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed…

  • CVE-2024-52867HigNov 17, 2024
    risk 0.46cvss 8.1epss 0.00

    guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (e.g., for setuid and setgid programs) are properly addressed. The vulnerability can be remediated within the product via certain…

  • CVE-2024-49504HigNov 13, 2024
    risk 0.46cvss —epss 0.00

    grub2 allowed attackers with access to the grub shell to access files on the encrypted disks.

  • CVE-2024-9191HigNov 1, 2024
    risk 0.46cvss 7.1epss 0.00

    The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers in a compromised device to retrieve passwords associated with Desktop MFA passwordless logins. The vulnerability was discovered…

  • CVE-2024-40805HigJul 29, 2024
    risk 0.46cvss 7.1epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. An app may be able to bypass Privacy preferences.

  • CVE-2023-38291HigApr 22, 2024
    risk 0.46cvss 7.1epss 0.00

    An issue was discovered in a third-party component related to ro.boot.wifimacaddr, shipped on devices from multiple device manufacturers. Various software builds for the following TCL devices (30Z and 10L) and Motorola devices (Moto G Pure and Moto G Power) leak the Wi-Fi MAC…

  • CVE-2024-22428HigJan 16, 2024
    risk 0.46cvss 7.0epss 0.00

    Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and execute arbitrary code on the affected system. Dell recommends customers upgrade at the earliest…

  • CVE-2023-5623HigOct 26, 2023
    risk 0.46cvss 7.0epss 0.00

    NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges where NNM is installed to a non-standard location

  • CVE-2022-33877HigJun 13, 2023
    risk 0.46cvss 7.0epss 0.00

    An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a local authenticated attacker to tamper…

  • CVE-2023-28079HigMay 30, 2023
    risk 0.46cvss 7.0epss 0.00

    PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains Insecure File and Folder Permissions vulnerability. A regular user (non-admin) can exploit the weak folder and file permissions to escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM.

  • CVE-2023-28724HigMay 3, 2023
    risk 0.46cvss 7.1epss 0.00

    NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager.   Note: Software versions which have reached End of Technical Support (EoTS) are not…

  • CVE-2022-4568HigMay 1, 2023
    risk 0.46cvss 7.0epss 0.00

    A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges.

  • CVE-2023-27647HigApr 14, 2023
    risk 0.46cvss 7.1epss 0.01

    An issue found in DUALSPACE Lock Master v.2.2.4 allows a local attacker to cause a denial of service or gain sensitive information via the com.ludashi.superlock.util.pref.SharedPrefProviderEntryMethod: insert of the android.net.Uri.insert method.

  • CVE-2023-25542HigApr 6, 2023
    risk 0.46cvss 7.0epss 0.00

    Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to escalated privileges.

  • CVE-2023-0181HigApr 1, 2023
    risk 0.46cvss 7.1epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory permissions are not correctly checked, which may lead to denial of service and data tampering.